[Документация Yandex Cloud](../../../index.md) > [Yandex Key Management Service](../../index.md) > [Справочник CLI (англ.)](../index.md) > [symmetric-crypto](index.md) > generate-data-key

# yc kms symmetric-crypto generate-data-key

Generate data key and encrypt it with specified symmetric key

#### Command Usage

Syntax:

`yc kms symmetric-crypto generate-data-key <SYMMETRIC-KEY> [Flags][Global Flags...]`

#### Flags

#|
||Flag | Description ||
|| `--id` | `string`

Symmetric key id. ||
|| `--name` | `string`

Symmetric key name. ||
|| `--version-id` | `string`

Symmetric key version id to encrypt data key. Otherwise primary version of symmetric key will be used. ||
|| `--aad-context-file` | `string`

Additional authenticated data file. Otherwise encrypt data key without aad context. ||
|| `--data-key-spec` | `string`

Required. Encryption algorithm and key length for the generated data key. Values: 'aes-128', 'aes-192', 'aes-256', 'aes-256-hsm', 'gost-r-3412-2015-k' ||
|| `--skip-plaintext` | Won't write generated data key as plaintext. ||
|| `--data-key-plaintext-file` | `string`

File to write generated data key as plaintext. ||
|| `--data-key-ciphertext-file` | `string`

Required. File to write encrypted data key. ||
|#

#### Global Flags

#|
||Flag | Description ||
|| `--profile` | `string`

Set the custom configuration file. ||
|| `--debug` | Debug logging. ||
|| `--debug-grpc` | Debug gRPC logging. Very verbose, used for debugging connection problems. ||
|| `--no-user-output` | Disable printing user intended output to stderr. ||
|| `--retry` | `int`

Enable gRPC retries. By default, retries are enabled with maximum 5 attempts.
Pass 0 to disable retries. Pass any negative value for infinite retries.
Even infinite retries are capped with 2 minutes timeout. ||
|| `--cloud-id` | `string`

Set the ID of the cloud to use. ||
|| `--folder-id` | `string`

Set the ID of the folder to use. ||
|| `--folder-name` | `string`

Set the name of the folder to use (will be resolved to id). ||
|| `--endpoint` | `string`

Set the Cloud API endpoint (host:port). ||
|| `--token` | `string`

Set the OAuth token to use. ||
|| `--impersonate-service-account-id` | `string`

Set the ID of the service account to impersonate. ||
|| `--no-browser` | Disable opening browser for authentication. ||
|| `--format` | `string`

Set the output format: text (default), yaml, json, json-rest. ||
|| `--jq` | `string`

Query to select values from the response using jq syntax ||
|| `-h`, `--help` | Display help for the command. ||
|#